← All Roles

Agent Registry Administrator

Enabled
Versionv1
Date Added2026-06-21
Categoryidentity
Assignment Modeallowed
Built-inYes
Template ID6b942400-691f-4bf0-9d12-d8a254a2baf5

Description

Manage all aspects of the Agent Registry service in Microsoft Entra ID

Details

Assign the Agent Registry Administrator role to users who need to do the following tasks:

  • Manage metadata for AI agents in Microsoft Entra ID
  • Manage collections and visibility of agents
  • Assign Agent Registry-specific roles to other users or agents to access the registry

Directory Actions1

  • microsoft.agentRegistry/allEntities/allProperties/allTasks

Graph API Permissions11

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • AgentCard.Read.All
  • AgentCard.ReadWrite.All
  • AgentCardManifest.Read.All
  • AgentCardManifest.ReadWrite.All
  • AgentCollection.Read.All
  • AgentCollection.ReadWrite.All
  • AgentCollection.ReadWrite.Global
  • AgentInstance.Read.All
  • AgentInstance.ReadWrite.All
  • AgentRegistration.Read.All
  • AgentRegistration.ReadWrite.All